Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2025-21193
Active Directory Federation Server Spoofing Vulnerability
Windows Server 2016
10.0.14393.7699 / 10.0.17763.6775+
MEDIUM 6.1
CVE-2024-0590
The Microsoft Clarity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.3. This is due to mi…
Clarity
0.9.4+
MEDIUM 6.8
CVE-2024-21381
Microsoft Azure Active Directory B2C Spoofing Vulnerability
Azure Active Directory
Patch available
MEDIUM 5.4
CVE-2023-24920
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Dynamics 365
9.0.45.11 / 9.1.16.20+
HIGH 7.6
CVE-2021-41372
A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing H…
Power Bi Report Server
Patch available
MEDIUM 6.5
CVE-2020-1103
An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site…
Sharepoint Enterprise Server
Patch available
HIGH 8.8
CVE-2019-1259
A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site reques…
Sharepoint Foundation
Patch available
HIGH 8.8
CVE-2019-1261
A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site reques…
Sharepoint Enterprise Server
Patch available
MEDIUM 6.5
CVE-2019-0996
A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, resulting in a cross-site reque…
Azure Devops Server
Patch available
MEDIUM 6.5
CVE-2018-0785
ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Cross Si…
Asp.net Core
Patch available
HIGH 8.8
CVE-2017-11876
Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read content that they are no…
Project Server
Patch available
MEDIUM 6.8
CVE-2015-1771EPSS 6%
Cross-site request forgery (CSRF) vulnerability in the web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allows remote a…
Exchange Server
Mitigation only
MEDIUM 6.8
CVE-2010-3213EPSS 8%
Cross-site request forgery (CSRF) vulnerability in Microsoft Outlook Web Access (owa/ev.owa) 2007 through SP2 allows remote attackers to hijack the a…
Outlook Web Access
No fix yet